1. Controller
The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:
PanelWave — Jens Hoppe
c/o RUFFINI Creative Hub
Sendlinger Straße 1
80331 München
Deutschland
Phone: +49 089 - 18 96 59 600
Email: privacy@panelwave.org
2. Scope and Roles
This Privacy Policy applies to:
- the marketing website at panelwave.org,
- the PanelWave CMS at app.panelwave.org (the authoring and publishing platform for creators),
- works published or previewed through PanelWave infrastructure and rendered by the PanelWave Player, and
- transactional emails sent by the platform.
PanelWave acts in two distinct roles:
- PanelWave as controller: for the data of website visitors, newsletter subscribers, prospects, and registered creators (including their team members), PanelWave is the controller under data protection law.
- PanelWave as processor: for the data of readers of published works (for example reading analytics or purchase entitlements) that creators process through PanelWave, the respective creator (or their team) is the controller. PanelWave processes this data solely on the creator's behalf on the basis of a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR. See section 12 for details.
The open-source PanelWave Player is also available as a library that third parties can host and embed on their own websites. Where a work is hosted entirely outside PanelWave infrastructure, the operator of that website is responsible for any data processing there; this policy does not apply to such deployments.
3. Hosting and Server Logs
PanelWave systems (application servers, databases, queues, object storage, and backups) are operated on infrastructure of Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in data centers located in Germany. The principle of EU data residency applies: databases, uploaded assets, and backups remain in EU data centers. A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider.
Server log files: when you access our websites and applications, the server infrastructure automatically processes information transmitted by your browser: IP address, date and time of access, requested URL, HTTP status code, transferred data volume, referrer URL, and browser type and version (user agent). This data is used to ensure stable operation, diagnose errors, and defend against attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and reliable operation). Log data is stored for a short period only and then deleted, unless it is required to investigate a security incident.
Error reporting: when a technical error occurs in the PanelWave CMS (in your browser or on our servers), an error report is sent to our own error-tracking system (GlitchTip, operated by us on the Hetzner infrastructure described above; no third party receives the data). A report contains the error type and message, the program location where it occurred (stack trace), the affected page address without query parameters, the application version, and your browser type and version (user agent); your IP address is processed when the report is transmitted. Reports contain no account name, email address, or content of your works. They are used solely to find and fix defects. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a reliable, error-free service). Error reports are deleted automatically after 90 days.
4. Visiting the Marketing Website
You can visit panelwave.org without providing any personal data.
- We set no cookies for analytics or marketing purposes on the marketing website.
- We use no third-party tracking or advertising networks and embed no social media plugins.
Only the server log files described in section 3 are generated.
5. Contacting Us
If you contact us by email (for example hello@panelwave.org) or via the contact form on this website, we process your email address, your name, the subject, and the content of your message in order to handle your inquiry. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering into, or performance of, a contract) or Art. 6(1)(f) GDPR (legitimate interest in answering inquiries). The contact form uses an invisible anti-spam field; no CAPTCHA service is embedded.
Contact inquiries are deleted once they have been dealt with conclusively, unless statutory retention obligations (for example for business correspondence) require longer storage.
6. Newsletter
If you subscribe to our newsletter, we process your email address and the signup source (which page you subscribed from). We use a double opt-in procedure: you receive a confirmation email and your subscription only becomes active once you confirm it. We log the confirmation in order to demonstrate consent.
The legal basis is your consent, Art. 6(1)(a) GDPR. You can withdraw your consent at any time with effect for the future — every newsletter contains an unsubscribe link, or you can email privacy@panelwave.org. For sending the newsletter we use the email service provider named in section 15; recipient addresses are shared with that provider solely for dispatch.
7. Creator Accounts (PanelWave CMS)
7.1 Registration and profile
When you register for the PanelWave CMS we collect your email address, a name, and a password. Passwords are stored exclusively as salted cryptographic hashes (bcrypt or PBKDF2-HMAC-SHA256) — never in plain text. Sign-in via a single sign-on provider (OIDC) is possible; in that case we store the provider's user reference instead of a password. During use, optional profile data may be added: display name, avatar image, short bio, location, website URL, interface preferences (theme, editing locale, notification settings). The legal basis is Art. 6(1)(b) GDPR (performance of the contract).
The free plan can be used without providing payment data.
7.2 Sign-in, sessions, and account security
- Authentication uses short-lived access tokens and rotating refresh tokens. For each active session we store the IP address and browser identifier (user agent) in a session registry so that we can detect account misuse and show you your active sessions, which you can revoke individually. Refresh tokens are stored only as SHA-256 hashes. The legal basis is Art. 6(1)(f) GDPR (account security).
- Session tokens are stored in your browser's local storage or session storage (technically required; no consent needed).
- You can optionally enable two-factor authentication (TOTP); recovery codes are stored only as hashes.
- Email address changes require confirmation via a verification link sent to the new address. Password reset links are single-use and expire after one hour; the tokens are stored only as hashes.
- Security-relevant administrative actions are recorded in an append-only audit log (actor, action, timestamp, IP address); legal basis Art. 6(1)(f) GDPR.
7.3 Teams and invitations
Creators can invite team members (for example co-authors, artists, translators) by email with a role assignment. We process the invited person's email address to deliver the invitation; the legal basis is Art. 6(1)(b) GDPR.
7.4 Support and impersonation
To help resolve problems, authorized PanelWave support staff can temporarily access an account (“impersonation”) under documented rules: a reason must be recorded, the access is limited to 30 minutes, cannot change passwords, email addresses, security or payment settings, is fully logged, and you are notified by email whenever it occurs. The legal basis is Art. 6(1)(b) GDPR.
8. Content, Assets, and Storage
Artwork, audio, video, scripts, and other files you upload are stored in S3-compatible object storage on the EU infrastructure described in section 3. Access to non-public files is granted via short-lived signed URLs. Published works are delivered via a content delivery network (CDN). Uploaded content may itself contain personal data (for example photographs of people); as between you and PanelWave, you are responsible for having the necessary rights to the content you upload.
9. AI-Assisted Features
The PanelWave CMS offers optional AI-assisted authoring features. These run only when you actively use them, and only the content required for the specific feature is transmitted:
- Script import and page splitting (OpenAI): when you use the script importer or the AI page-split importer, your script text and/or uploaded comic page images are transmitted to OpenAI (OpenAI Ireland Ltd., Dublin, Ireland; parent: OpenAI, L.L.C., USA) to detect structure, panels, and layout. API usage terms apply under which the transmitted content is not used to train AI models.
- Machine translation (DeepL): translatable text of your work can be pre-translated via DeepL SE (Maarweg 165, 50825 Cologne, Germany).
- Text-to-speech (ElevenLabs): if you generate voiceover audio, the relevant dialogue text and voice settings are transmitted to ElevenLabs, Inc. (USA).
- Image upscaling (Freepik / Magnific): if you use the upscaler, the selected image is transmitted to Freepik Company S.L. (Málaga, Spain) for AI-based enhancement.
- AI assistants you connect (MCP): PanelWave offers an interface based on the Model Context Protocol through which AI assistants of your choice (for example Claude by Anthropic, ChatGPT by OpenAI, or Cursor) can read and edit your works on your behalf. The assistant only acts after you connect it and grant permissions, and it receives the content of your works that its requests ask for. The provider of the assistant processes that content under your own agreement with that provider; PanelWave does not pass your data to it on its own initiative. For connected apps we store the app's name and address, the permissions you granted, the time of connection and last use, and access tokens in hashed form. For security and abuse prevention we log every action an assistant performs (app, action, work, outcome, time and duration — not the text of your request); legal basis Art. 6(1)(f) GDPR. You can disconnect an app or revoke a personal access token at any time in your profile; changing or resetting your password ends all connections.
The legal basis is Art. 6(1)(b) GDPR (provision of the features you invoke). Where data is transferred to third countries, section 15 applies. Please do not include personal data of third parties in content submitted to AI features unless you have a legal basis to do so.
10. Payments
Where paid plans or reader monetization are offered, payment processing is handled by Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland; parent: Stripe, Inc., USA) and/or PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg). Credit card and bank details are captured directly by the payment provider and are never stored on PanelWave servers; we store only references (for example customer ID, subscription status, webhook events). For reader purchases via Stripe Connect, the respective creator (team) is the merchant of record and the reader's contractual partner; PanelWave stores the checkout email address only in hashed (pseudonymized) form to grant access entitlements.
The legal bases are Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (commercial and tax law obligations). Invoices are subject to statutory retention periods (up to 10 years under German law).
11. Reader Analytics for Creators
Creators can view analytics about how their published works are read (sessions, panel views, dwell times, completion rates, funnels). PanelWave processes the underlying reader events as a processor on behalf of the creator — see section 12 for what is collected and how. Creator dashboards show aggregated results; platform-level statistics available to PanelWave (for example total sessions per day) are derived exclusively from aggregated data without personal reference.
12. Readers of Published Works (Processing on Behalf of Creators)
If you read a work published through PanelWave, the controller is the respective creator (or their team). PanelWave processes reader data on the creator's behalf pursuant to Art. 28 GDPR under our Data Processing Agreement. The following applies to the technical implementation:
- No account, no cookies: reading does not require an account, and the PanelWave Player sets no cookies and no persistent reader identifier.
- Reading analytics (consent-gated): the Player collects reading events (for example panel views, dwell time, choices, completion) only where the work has analytics enabled and, by default, only after consent. Events carry a randomly generated session ID that exists only in memory and changes on every visit — it cannot be used to recognize you across visits. The analytics endpoint does not store your IP address or user agent; the IP address is used transiently for rate limiting only. Device type and language reported by the Player are stored in aggregated statistics.
- Story progress in your browser: works can save story variables (for example choices you made, reading progress) in your browser's local storage. This data remains on your device and is not transmitted to PanelWave.
- Bonus content and sharing: when you view certain bonus content (“extras”) or use a share function, a record including IP address and user agent may be stored to measure reach and prevent abuse.
- Purchases and paywalls: if a creator sells access to a work, the purchase runs through the payment provider (section 10). To restore your access, PanelWave stores your checkout email address in hashed (pseudonymized) form together with the entitlement.
Readers should direct data subject requests (access, erasure, etc.) primarily to the respective creator; requests received directly by PanelWave are forwarded to the creator where attribution is possible.
13. Data Retention
We store personal data only as long as necessary for the respective purpose or as required by law:
- Creator accounts: upon account deletion, account data and uploaded content are deleted or anonymized after a grace period of 30 days. You can export your works beforehand.
- Session registry: expired and revoked sessions are removed regularly; session records are kept no longer than 90 days after expiry.
- Raw reading events: aggregated into statistics and deleted or anonymized after 24 months at the latest.
- Audit logs: retained for as long as required for security and accountability purposes.
- Actions of connected AI assistants (MCP): deleted automatically after 12 months.
- Invoices and accounting records: statutory retention of up to 10 years (German GoBD/AO); exempt from earlier deletion and archived immutably.
- Server logs: short-term storage, then deletion (see section 3).
- Error reports: deleted automatically after 90 days (see section 3).
14. Data Security
We implement technical and organizational measures pursuant to Art. 32 GDPR, including:
- transport encryption (TLS) on all connections,
- password storage exclusively as salted bcrypt/PBKDF2 hashes; refresh tokens, reset tokens, and recovery codes stored only as SHA-256 hashes,
- tenant separation of customer data at the application and database level,
- role-based access control (team roles and separate platform admin roles) and optional two-factor authentication,
- an append-only audit log for administrative actions, including logged and time-boxed support access,
- rate limiting on authentication and public endpoints,
- short-lived signed URLs for file access,
- backups stored exclusively in EU data centers.
15. International Transfers and Recipients
Our service providers (processors) are listed in Annex 3 of the DPA. Where data is transferred to service providers outside the EU/EEA (in particular USA: OpenAI, ElevenLabs, Stripe, Inc.), the transfer is based on an adequacy decision of the EU Commission (Art. 45 GDPR — for example the EU-U.S. Data Privacy Framework) or on the EU Standard Contractual Clauses (Art. 46 GDPR), supplemented by additional safeguards where appropriate. Newsletter and transactional email dispatch uses Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany), with processing in the EU.
16. Your Rights
You have the following rights vis-à-vis the respective controller:
- access to the data processed about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- withdrawal of consent with effect for the future (Art. 7(3) GDPR).
An informal message to privacy@panelwave.org suffices. If your request as a reader concerns data we process on behalf of a creator, please contact the creator first; otherwise we will forward your request.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for PanelWave is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
17. Children
The PanelWave CMS is not directed at children under 16, and we do not knowingly collect personal data from children. Individual works may carry their own age recommendations set by the creator.
18. No Automated Decision-Making
Automated individual decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.
19. Changes to This Policy
We update this Privacy Policy when our services or the legal situation change. The current version published on this page applies. We will notify registered creators of material changes by email or an in-app notice.